CVE-2017-8144
Last modified
CVE-2017-8144 is a vulnerability of currently unknown severity. Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei smartphones with software the versions before CAM-L03C605B143CUSTC605D003,the versions before Prague-L03C605B161,the versions before Prague-L23C605B160,the versions before MHA-AL00C00B225,the versions before LON-AL00C00B225,the versions before VTR-AL00C00B167,the versions before VTR-TL00C01B167,the versions before VKY-AL00C00B167,the versions before VKY-TL00C01B167 have a resource exhaustion vulnerability due to configure setting. An attacker tricks a user into installing a malicious application, the application may turn on the device flash-light and rapidly drain the device battery.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Honor 5A,Honor 8 Lite,Mate9,Mate9 Pro,P10,P10 Plus Huawei smartphones with software the versions before CAM-L03C605B143CUSTC605D003,the versions before Prague-L03C605B161,the versions before Prague-L23C605B160,the versions before MHA-AL00C00B225,the versions before LON-AL00C00B225,the versions before VTR-AL00C00B167,the versions before VTR-TL00C01B167,the versions before VKY-AL00C00B167,the versions before VKY-TL00C01B167 have a resource exhaustion vulnerability due to configure setting. An attacker tricks a user into installing a malicious application, the application may turn on the device flash-light and rapidly drain the device battery.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Honor 5a Firmware | < cam-l03c605b143custc605d003 |
| Huawei | Honor 8 Lite Firmware | < prague-l03c605b161 |
| Huawei | Honor 8 Lite Firmware | < prague-l23c605b160 |
| Huawei | Mate 9 Firmware | < mha-al00c00b225 |
| Huawei | Mate 9 Pro Firmware | < lon-al00c00b225 |
| Huawei | P10 Firmware | < vtr-al00c00b167 |
| Huawei | P10 Firmware | < vtr-tl00c01b167 |
| Huawei | P10 Plus Firmware | < vky-al00c00b167 |
| Huawei | P10 Plus Firmware | < vky-tl00c01b167 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8144?
How severe is CVE-2017-8144?
How do I fix CVE-2017-8144?
Are you affected by CVE-2017-8144?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
